Skip to content
Back to home

Privacy Policy

Last updated: July 29, 2026

1. Service identity and scope

This policy explains what Crypto Portfolio Tracker collects, why we use it, and the choices available when you use our mobile app and website. The app is a tracking tool: it does not custody crypto and never asks for wallet private keys or seed phrases.

The Apple App Store listing identifies Gurgen Abagyan as the seller. Crypto Portfolio Tracker is the service name used throughout this policy. Privacy requests go to the contact address in section 10.

2. Information we collect

  • Account information: your email address and, when an authentication provider supplies them, your name or profile image. Authentication infrastructure also stores provider account identifiers, password credential hashes when password sign-in is used, sessions, refresh-token records, verification records, and sign-in rate-limit records.
  • Portfolio information: portfolios, holdings, transactions, and preferences you add. This data is stored with your account so it can sync across sessions.
  • Exchange credentials: if you choose Binance auto-sync, the API key and secret you provide are stored in the Convex account database and returned to your signed-in app so it can sign balance requests sent directly to Binance. These values may also be included in the app's local persisted query cache. Use a dedicated read-only key and keep trading and withdrawals disabled.
  • AI requests: when you use the assistant, the app sends portfolio names; asset symbols, quantities, and estimated values; and up to five chat messages total, including the current question, through our server to OpenAI.
  • Website analytics: after you choose Allow analytics, Google Analytics may collect device, browser, approximate location, page, and interaction data, including App Store link clicks. Google Analytics can set first-party identifiers such as _ga and_ga_*; Google documents a default expiry of up to two years for these cookies. The website stores your analytics choice in browser local storage.

3. How we use information

We use information to provide account access, sync and display your portfolios, operate optional exchange connections and AI features, maintain security, respond to support requests, and improve the app and website. We do not sell personal information or use your exchange credentials to place trades or withdrawals.

4. Providers and data flows

  • Convex provides authentication infrastructure and the account database.
  • Apple and Google support optional provider sign-in, and Resend delivers email verification codes.
  • Binance receives signed balance requests when you enable exchange sync. CoinGecko supplies market data.
  • OpenAI processes optional AI requests. Google Analytics processes website usage only after analytics consent.

5. AI data handling

The current app keeps chat messages in the active screen's memory and does not write chat transcripts to the account database. OpenAI states that API data is not used to train its models unless the API account owner explicitly opts in. Under OpenAI's default API controls, abuse-monitoring logs may include prompts and responses and may be retained for up to 30 days. We do not claim that Zero Data Retention or regional processing is enabled.

6. Your choices and deletion

  • Exchange auto-sync is optional; manual tracking remains available.
  • Removing an exchange connection deletes its stored connection record. Revoke the key in Binance as well.
  • The Profile screen includes Delete Account, which permanently deletes the account and its portfolios, holdings, transactions, exchange connections, authentication accounts, sessions, associated refresh tokens, verification records, and session verifiers from the app database.
  • Signing out or deleting the account clears the app's persisted query cache. Clearing the app's storage removes other locally stored app data. Server-side account deletion does not itself control backups, authentication rate-limit records, or records retained by independent providers under their policies.
  • You can contact us to request access, correction, or deletion of account data.
  • You can decline optional website analytics or reopen Analytics in the footer to change your choice. Declining disables analytics collection for the site and removes readable Google Analytics cookies set for this domain. Browser privacy controls, cookie clearing, and content blockers remain available.

7. Retention

Account and portfolio data remain in the app database until you delete the relevant record or your account. Exchange credentials remain until you remove the connection or delete the account. Selected query results may remain in local app storage until the cache expires or app storage is cleared. Provider-side logs, backups, analytics, and legal retention follow the applicable provider policies.

8. International processing

Convex, OpenAI, Google, Apple, Resend, Binance, and CoinGecko may process information in countries other than yours according to their infrastructure and policies. The current app does not offer a processing-region selector.

9. Security

We use authentication and access checks intended to limit account records to the signed-in user, but no system can guarantee absolute security. Authentication sessions use operating-system secure storage on iOS and Android. This policy does not claim that exchange credentials have end-to-end encryption or an independent security certification. Keep exchange keys read-only, use unique account credentials, and revoke a key immediately if you suspect misuse.

See the separate security page for the current implementation boundaries and reporting process.

10. Contact

Questions or privacy requests can be sent to support@crypto-portfolio-tracker.app.